Cyber Security and Resilience (Network and Information Systems) Bill Debate
Full Debate: Read Full DebateLord Clement-Jones
Main Page: Lord Clement-Jones (Liberal Democrat - Life peer)Department Debates - View all Lord Clement-Jones's debates with the Department for Digital, Culture, Media & Sport
(1 month ago)
Grand CommitteeMy Lords, I think that we are in the final furlong. In moving my Amendment 92C, I will also speak to the closely aligned Amendment 95C under my name. These amendments raise a profound and non-negotiable constitutional principle. They respond directly to the almost always authoritative recommendations of the Delegated Powers and Regulatory Reform Committee in its seventh report of this Session and are strongly supported by the principles laid down by the Select Committee on the Constitution in its third report. Together, these amendments seek to delete two deeply objectionable provisions that represent a classic example of secondary legislation creep—provisions where the Executive are seeking a blank cheque to unilaterally rewrite the rules.
Amendment 92C targets Clause 37 and seeks to leave out subsection (7). Under the Bill as drafted, Clause 37(7) grants the Secretary of State the unilateral power to make regulations to amend the Act to change and potentially dilute the consultation and parliamentary scrutiny requirements that apply to a code of practice. This is a Henry VIII power of quite an extensive kind. In the Government’s original delegated powers memorandum of November 2025, the department, as it then was, argued that this power was necessary to allow flexibility in case a 40-day parliamentary scrutiny period became, in its words, “unfeasible” or
“a detriment to the quality of … a code”.
But as the Delegated Powers Committee correctly noted in its seventh report, the rules governing how Parliament scrutinises the Executive must be set by Parliament in primary legislation; they should not be subject to the administrative convenience of a Minister. Allowing a Minister to use secondary legislation to alter or weaken the very procedural safeguards that this House has debated is not constitutionally correct. The committee’s recommendation is clear and unambiguous: subsection (7) must be removed.
That brings me to Amendment 95C, which seeks to leave out Clause 40(5). Clause 40 requires the Secretary of State to lay a report before Parliament on the operation of this cyber security legislation. However, subsection (5) grants the Secretary of State the power to amend this primary legislation via regulations to change the matters to be covered in those same reports. Again, in their original November 2025 memorandum, the Government defended this by claiming that they needed flexibility to ensure that reports could be expanded over time as technology matures.
With the greatest respect, that argument is entirely spurious. If the Government merely wish to report on more things, they are already fully entitled to include voluntary supplementary chapters in their reports. But by granting themselves a statutory power to amend the legal requirements of Clause 40, they are taking the power to delete or dilute the core mandatory reporting obligations that Parliament has put in the Bill. They would, in effect, be legally empowered to write their own report cards, deciding behind closed doors what they must disclose to Parliament and what they can quietly omit, including critical scrutiny over how they have used the vast delegated powers under Clause 29(1).
The Delegated Powers Committee was again clear. This power is inappropriate, lacks coherent justification and should be deleted from the Bill. The Select Committee on the Constitution too, in its third report, expressed serious anxieties about the overall design of the legislation. It warned that this is a framework Bill that relies far too heavily on secondary regulations to establish the actual perimeters of national cyber resilience.
When a Bill already delegates such sweeping unprecedented powers to the Executive, amplified by the amendments to introduce a parallel high-risk vendor framework, laid on 24 August and discussed on the first day of this Committee, it is doubly important that the statutory channels of parliamentary oversight remain supreme. We cannot allow the Government to use secondary regulations to dismantle the guardrails that keep them accountable. I urge the Minister to accept these common-sense, committee-backed corrections and agree to delete Clause 37(7) and Clause 40(5) before Report. I beg to move.
My Lords, I thank the noble Lord, Lord Clement-Jones, for opening the final day of Committee. For a Bill of such importance, I am surprised at the speed of our progress. However, if quantity has been low, quality has more than compensated.
I agree with the noble Lord that this Committee deserves rather more justification from the Government as to the need for the powers they are granting themselves. The Delegated Powers and Regulatory Reform Committee described the Clause 37(7) power as “unusual” and “novel”, capable of watering down requirements for consultation as it is not constrained by set criteria. The Government’s justification thus far for this power is that it allows them to
“prioritise the content of the code of practice, rather than arbitrary requirements”.
It sounds to me rather as if the Government’s position is that they see any set requirements for consultations and codes of practice as arbitrary. If that is the case—I would appreciate clarification from the Minister—I have to agree with the committee’s description that the position is “quite extraordinary”.
By the way, I noted this morning that the Chancellor of the Duchy of Lancaster has demanded an end to the culture of consultation. I fear that that will be quite a wrench for the former DSIT and its functions, it having launched four new consultations on a single day in July without having responded to the more than 11,000 responses to the AI and copyright consultation. We are already unclear about the machinery of government for that former department. Can the Minister tell us whether its existing and planned consultations will continue or whether today’s announcement represents a fundamental change of approach?
It is not clear why the power conferred by Clause 40(5) has to be sufficiently broad to allow the Government to water down the contents of reports on network and information systems. Could it not be amended, as the committee has recommended, so that the power cannot be used to reduce the requirements to report? It is not unreasonable to question whether the Government really need these extensive powers. Your Lordships’ Committee deserves at least more justification than the Government describing set criteria as arbitrary. I appreciate the need for flexible and adaptive approaches to legislating for fast-moving technologies, but that must come with accountability and I am not sure that we have the balance right at this point. I look forward to the Minister’s response.
Baroness in Waiting/Government Whip (Baroness Ramsey of Wall Heath) (Lab)
I thank the noble Lord for his Amendments 92C and 95C, and note that these amendments were recommended by the Delegated Powers and Regulatory Reform Committee in its report of 17 July. Some noble Lords may be aware that, until very recently, I was the chair of that committee. I am wondering how best to describe myself: am I gamekeeper turned poacher or poacher turned gamekeeper? I had better let noble Lords decide at the end of my responses.
These delegated powers were included to prevent a scenario where procedure takes priority over the best possible products, whether that be a code of practice or a report on the legislation. The delegated powers will not allow Ministers to bypass Parliament. They are about ensuring that government can respond quickly and effectively to new threats and new technologies that could undermine our national security. The law has always been slower than innovation, and it is unlikely to catch up unless we change our approach. Ministers must provide clear justification and carry out assessments before regulations are laid before Parliament.
On the code of practice, we anticipate that any code will be updated from time to time to remain effective, in line with the latest recommended good practice, evolving threat information and emerging technologies. Any revisions and reissues of a code of practice must first be consulted on with relevant stakeholders before they are effective.
On consultations, it might be above my pay grade to comment so soon after the Chancellor of the Duchy of Lancaster has commented, but I am sure that my noble friend the Minister will have a further response to that at some point, possibly in writing.
I assure noble Lords that the Government are carefully considering the committee’s recommendations and the views of noble Lords today, and will reflect accordingly ahead of Report. My noble friend the Minister will respond formally to the Delegated Powers and Regulatory Reform Committee in the usual manner ahead of Report.
I thank the Minister for her response, which was the reverse of the usual ministerial response—the sting was not in the tail but at the beginning. The end was much more conciliatory, given that she said the Government will consider taking on board the DPRRC’s recommendations before Report. I very much hope they do. At this stage in Committee, of course, nothing gets decided, but I assure the Minister that, if this continues, and the Government do not respond in some shape or form to both those pretty solid recommendations from the committee, we will bring this back on Report.
When I say that the sting was in the beginning of the response, I mean that it was a bit surprising, given that the Minister has been the chair of the committee and knows the seriousness with which we all take its recommendations. A huge amount of work goes into the detail, and she knows how much store we place on the recommendations. I hope that she will use all her influence to make sure that the Government introduce before Report something along the lines of what I have produced. In the meantime, I beg leave to withdraw Amendment 92C.
My Lords, all the amendments that I have put down to the Bill are derived from evidence we received on the National Resilience Select Committee. I am sorry that I was not here last week to address those that came up then, and I am very grateful to my noble friend Lord Clement-Jones for presenting them for me.
Several members of the Select Committee, including me, were in Finland last week looking at its preparedness for attack. Finland has faced the threat from its long border with Russia throughout the history of its country, and its preparedness on a whole-of-society basis is extremely impressive. Although we do not have a long border with Russia to focus our minds, we know that cyber attacks can immediately undermine our whole society and economy. One of the things we heard on our Select Committee is that not only are many companies unprepared for cyber attacks but that there is a shortage of skills in this area.
This amendment is seeking to move things forward. The proposed new clause would
“give the UK Cyber Security Council statutory functions to validate qualifications, to monitor the supply of and demand for cyber security professionals in the areas covered by the Bill, and to audit whether regulated organisations employ certified professionals—a ‘competence mandate’ for the regime”.
I have received some useful information from the sector, which welcomes my attempt to try to ensure that we have sufficient cyber professionals and that there is a mechanism by which they are certified. There are analogies with the certification of medical professionals, for example. Their certification is conducted independently, and I recognise the importance of that. What I am arguing for here is the principle and not necessarily the route suggested by my amendment. How this is best done can be further discussed between Committee and Report.
The National Cyber Security Centre reported that nationally significant cyber incidents have more than doubled in a year. According to its survey, only 7% of UK businesses have formally reviewed the potential cyber security risk presented by their wider supply chain. Evidence to our Select Committee suggests that skills shortages are a key challenge here, especially for SMEs and those in the public sector. It is clear that cyber education, training and apprenticeships, and so on, must accompany these reforms.
The Bill places greater responsibility on organisations to identify and manage cyber risk. However, beyond those technological solutions, these obligations will require skilled professionals to carry them out. The Bill refers to the appointment of a “skilled person” in the context of a national security directive but does not delve into what constitutes a skilled person. I realise that this will change over time, but there should be ways of addressing this.
Neither does the Bill acknowledge the role of skilled persons in delivering its wider objectives. Those in the field have called on the Government to amend the Bill to require organisations to access a cyber security workforce that is qualified to recognise professional standards. We know that this skills shortage exists, weakening our national resilience. One report showed that 87% of organisations experienced at least one consequence due to skills need, so it is becoming strategically important to address this. The Government should use the Bill as an opportunity to professionalise the sector by committing to a cyber security workforce and skills strategy, and mandating that regulators and regulated entities use suitably skilled people for the purposes of compliance with the regulation.
Recognised professional qualifications and certifications anchored in international standards should be required so that we and the regulators are reassured that the work is being carried out to a certain standard. The UK Cyber Security Council was granted royal chartered status to establish a self-regulating, politically independent professional body, structured on proven models of other professional bodies such as the GMC. The UK needs to transition from a fragmented patchwork of varying certifications to a unified national standard of professional competence and ethical conduct.
Therefore, the Bill should recognise the council as the authority for setting and maintaining these standards. Given that the Bill aims to enhance the security and resilience of the UK and the critical sectors that underpin our economy, that needs to be assisted by a suitably skilled workforce to implement it. Of course we need to take further action to make sure that we train people, but this amendment is designed to help move this forward by ensuring that those in this area are sufficiently skilled. I beg to move.
My Lords, I was hoping that there would be other contributors—there will be a double-banking on this amendment.
I support Amendment 99, tabled by my noble friend. Throughout our deliberations on this Bill, the Government have placed enormous emphasis on imposing tough, outcomes-based statutory duties on operators and suppliers across our critical infrastructure, but we must confront an uncomfortable truth: we can pass the most sophisticated cyber security regulations in the world but, if our economy lacks the trained, qualified human beings required to design, implement and maintain those defences, those regulations remain completely meaningless. Without a professional workforce capability, this Bill merely codifies what ISC2 has rightly termed “compliance theatre”—an expensive box-ticking exercise that produces mountains of paperwork without making our national networks one bit safer.
Look at the scale of the crisis facing our domestic cyber workforce. In its landmark 2025-26 cyber security workforce study, ISC2 revealed that 52% of UK cyber security professionals identify severe skills shortages as their single greatest barrier to complying with cyber regulations. Further, 58% of organisations reported a critical or significant skills deficit, with an astonishing 87% suffering direct operational consequences from missed system patches and delayed vulnerability remediation to active security oversights. Across the civilian economy, the UK currently faces an 88% shortage of certified cyber practitioners. In an environment of such extreme scarcity, how on earth do the Government expect regulated water utilities, transport operators and medium-sized managed service providers to fulfil the heavy duties created by this Bill?
Amendment 99, from my noble friend, would provide a structural solution to this workforce crisis by placing the UK Cyber Security Council on a formal statutory footing. Crucially, as she explained, this connects directly to the definition of a skilled person under Clause 43. If the Government are serious about raising our national resilience floor, they must recognise that human competence is just as vital as technological hardware. By embedding the UK Cyber Security Council’s competence mandate in primary legislation, Amendment 99 would ensure that our cyber laws are backed by the skilled workforce needed to defend us.
I strongly urge the Minister to accept this amendment. By professionalising our cyber workforce, we would elevate this Bill from more than a compliance exercise to a genuine national capability.
My Lords, I intervene in support of the amendment in the name of the noble Baroness, Lady Northover. I do not want the Liberal Democrats to be on their own, so I hear the call from the noble Lord, Lord Clement-Jones. It brings me back to the coalition days, when I and the noble Baroness, Lady Northover, were once Ministers in the same department—so my support is heartfelt.
I support the substance of the amendment. As the noble Baroness, Lady Northover, says, it may not necessarily be the right amendment but the spirit behind it is absolutely one that the Government should recognise. I was a bit concerned when the noble Baroness was outlining the intention behind the amendment whether it could perhaps be seen as a burden on business, particularly when we talk about small businesses and the need to audit their cyber preparedness. However, to recall my contribution at Second Reading, I said at the time that, although we tend to debate cyber in the Chamber and other places as a great threat that we need to address, it is also a fantastic economic opportunity. I should declare that I am an adviser to a company called Digital Futures, which trains software developers. We do not train them in cyber but obviously the need to build up a skilled workforce in cyber is absolutely essential.
The noble Baroness, Lady Northover, referred to the patchwork of qualifications that exist in this area. It seems to me that the Government have a clear opportunity and a clear role to guide us through the maze and to put the National Cyber Security Centre on a statutory footing to give it the ultimate role in deciding the appropriate qualifications in cyber and to begin a sustained campaign to show young people, people returning to the workforce or people who are considering a new career that there is a route through to recognised, well set out cyber qualifications that will contribute to the national economy and our cyber resilience. I therefore wholeheartedly back this amendment.
I think we all share the sympathy that the noble Baroness, Lady Northover, has identified SMEs need. There are 5.7 million SMEs in the UK and many of them—indeed, most of them—will purchase what are relatively complex platforms. The noble Lord, Lord Londesborough, is extremely experienced in the SME sector; I have less experience than him, but I do have some. Hardly any of them will be able to employ anybody who is able to understand either the complexity of the platform that they have purchased or the highly dynamic threats to that platform that exist. There are many ways in which we need to raise our game and to help.
I personally think that, at least in the short term, the most important thing, which we have not discussed enough so far, is to require providers to supply safe products and, moreover, when they become vulnerable—which happens all the time, often unexpectedly—to patch those products for their customers immediately. The providers have a level of sophistication that the customers do not, and we have insufficiently focused on that in our discussion so far.
The second thing to mention—this is not really part of the Bill—is that the Government’s Cyber Essentials programme is very sound. The Minister quoted a figure the other day, which I forget, but only a trivial number of businesses have signed up and taken the pledge. This needs much more publicity and much more dynamism from within government to raise the understanding of the level of threat that SMEs face.
My Lords, I too support Amendment 100, in the name of my noble friend Lady Northover, and will add my support to the very useful speeches from the noble Lords, Lord Vaizey, Lord Birt and Lord Londesborough. I entirely agree with the noble Lord, Lord Vaizey, about the need to inject a sense of urgency into this. The noble Lords, Lord Birt and Lord Londesborough, asked some very fair questions, which went back to some of the debate we had on a single regulator and product liability, all of which are relevant to the kinds of duties that SMEs are under.
I welcome what the Minister had to say about the Government’s consciousness of the needs of SMEs, but this amendment would provide a blueprint for a much better form of support for SMEs. They account for 99% of all private sector businesses but, as the NCC Group and industry experts have repeatedly warned, they represent what might be described as the soft underbelly of our national supply chains. They are the prime targets for cyber criminals seeking a backdoor into critical infrastructure.
It is completely unrealistic to expect a 60-person small supplier to bear the same heavy compliance overheads as a multinational utility. A single ransomware attack can permanently destroy a small firm. Hostile state actors and ransomware syndicates are no longer focusing exclusively on attacking the fortified perimeters of FTSE 100 utilities or government departments; instead, they deliberately target smaller, resource-poor suppliers and niche contractors embedded in tier 2 or tier 3 of critical supply chains, using them as an easy, undefended backdoor into our critical national infrastructure.
Under the expanded critical supplier provisions in Clause 12 and the managed services duties in Clause 9, thousands of medium-sized businesses and specialised tech vendors will now be pulled directly into the statutory NIS regime, facing severe regulatory requirements under threat of multi-million pound penalties. However, as the Government’s own impact assessments acknowledge, there is a staggering what might be called resource asymmetry across UK businesses. A 50-person specialised component manufacturer or regional logistics provider does not have a dedicated chief information security officer or possess a 24/7 security operations centre and cannot afford to hire elite forensic incident response teams on £500-an-hour retainers. When a sophisticated ransomware attack hits a small business, it is frequently an existential event that forces insolvency.
During Committee stage in the Commons, when my honourable friend Freddie van Mierlo MP brought forward this proposal, the Minister in the Commons rejected it on the grounds that the Government already provide voluntary advice online. A downloadable PDF checklist on GOV.UK is not an incident response service. When a small critical supplier is locked out of its servers by a Russian ransomware gang at 2 o’clock on a Sunday morning, a generic website checklist is completely useless. It does not need advice to check its passwords; it needs an active, human, technical first responder to help it contain the malware, isolate compromised systems and safely recover its data.
Amendment 100 would bridge this capability gap by mandating a dedicated national support service modelled directly, as my noble friend explained, on the proven and globally respected Australian Cyber Security Centre’s framework. In Australia, the federal Government provide small and medium-sized businesses with free direct phone-in emergency technical support, active breach triage and hands-on recovery assistance. It has achieved extraordinary success in hardening Australia—
To continue, if the state is going to impose heavy, legally binding supply chain security duties on small businesses, backed by turnover-based fines, the state has a moral and strategic obligation to provide the operational tools needed to meet those standards. By establishing a free, Australian-style digital safety net under Amendment 100, we would turn the Bill from a purely punitive compliance exercise into a genuine co-operative national partnership for cyber resilience, and I urge the Minister to accept this vital common-sense amendment.
My Lords, I thank the noble Baroness, Lady Northover, for her amendment and, needless to say, I support the intention behind it. It is clearly right that, having placed several new duties on businesses and their vendors, the Government consider how to ensure that they are able to carry them out. This is particularly the case for SMEs, which are often far less resilient, less well-resourced and more vulnerable to cyber attacks than their larger counterparts. But, when thinking through this idea, I was trying to come up with some sort of framework to estimate the costs of such a provision, and I just could not arrive at a satisfactory estimate, except that they would be very considerable, particularly given the urgency, complexity and difficulty of incident response.
As I think the noble Lord, Lord Clement-Jones, and others mentioned, providing advice on a government website is cheap and useful, but providing urgent incident response is far from cheap. That begs the question: would it be funded by the companies benefiting from this directly or the taxpayer? I am not sure that either is wholly satisfactory. The actual costs of running such a programme will depend largely on how it would operate and the terms of service it would offer. I am very grateful to the noble Baroness, Lady Northover, for pointing to the Australian example; I confess that I was unaware of it before and would be interested to know what service it provides and to what level. It is incredibly hard to estimate how it will operate and what terms of service it will offer. The rate of cyber attacks is non-linear, the scale, nature and complexity of each attack will vary significantly and the number of staff needed or resources available for a response at any one time would necessarily be volatile and unpredictable.
My Lords, Amendment 148A stands in my name on the Marshalled List. This amendment would address a profound, structural and deeply disturbing gap in the judicial oversight and democratic accountability of the Bill. It represents a direct implementation of the authoritative recommendation of the Select Committee on the Constitution, in its third report of this Session.
Under Clause 50, the Secretary of State, acting as the direct enforcement authority for national security directions, is empowered to issue a unilateral confirmation decision that potentially imposes hugely significant financial penalties on non-compliant organisations. Under Clause 49, these penalties can reach a peak of up to £17 million or 10% of global turnover for commercial undertakings. Even for non-undertakings—such as our cash-strapped NHS trusts, local government authorities, or educational bodies—the penalty can be a crushing £17 million, with daily ongoing fines of up to £100,000 per day. Yet, under the Bill as currently drafted, the Government expect us to accept that the only avenue of legal recourse for an affected organisation to challenge these business-destroying fines is judicial review in the High Court.
Baroness Lloyd of Effra (Lab)
I resume with Amendments 174A and 174B, which were introduced by the noble Lord, Lord Markham. They would require the Secretary of State to create a register of “foreign powers” that pose a threat to UK cyber security, to review this register and to lay the report in Parliament. This is intended to inform the use of the powers granted under Part 4 of the Bill. The noble Lord is right that hostile foreign actors pose a clear risk to our essential services. National security is the first responsibility of any Government, which is why we are addressing these risks actively, including through the Bill.
The Bill will grant the Secretary of State important new powers to issue national security directions to regulated entities or regulators, where their compromise poses a national security risk. We will seek to strengthen the Government’s national security toolkit further, to protect our supply chains from hostile actors. That is why we put forward a package of amendments to introduce new powers that would enable the UK to address vendor-related cyber risks by hostile actors in our critical infrastructure supply chains. I look forward to engaging noble Lords further on this essential package ahead of Report.
Any decision to use the powers in the Bill will be informed by expert national security advice, including from GCHQ. The direction powers provide a strategic case-by-case basis to safeguarding our national security, irrespective of the specific actor. As a result, a country-specific approach lacks the nuance required to assess and respond comprehensively to all relevant risks. We also need to proceed responsibly in how we categorise and present these risks in the public sphere.
That is not to say that we shirk transparency about these kinds of risk. The Government are already able to communicate with Parliament and the public about such cyber risks where it is appropriate to do so. As the noble Lord, Lord Markham, set out, the NCSC annual report highlights risks posed by foreign actors; we work with the NCSC to mitigate these risks.
I note that noble Lords have confronted this question before, notably during the passage of the Telecommunications (Security) Act, where there was cross-party support for vendors to be assessed on a case-by-case basis, rather than by designating nations themselves as hostile actors. I hope that, in that vein, noble Lords are reassured that the Government have the tools to act strategically, acting on the right intelligence where hostile states seek to do us harm.
I thank the Minister for her response and the noble Lords, Lord Vaizey and Lord Markham, for their contributions. I cannot help feeling that the approach to this by the noble Lord, Lord Vaizey, is coloured by his history as a Minister. I can understand that because I saw the frustration within Ofcom over the type of judicial review. It was a particular type of judicial review: it was not a full merits-based appeal, but it allowed merits to be considered as part of the judicial review process. Subsequently, that was changed, which has probably calmed the way in which appeals are carried on.
However, in this particular case, although he said that he was not sighted as to the secrecy aspects of this, it was quite interesting to hear what the noble Lord, Lord Markham, had to say. He started by saying that he supported the amendment, then—rather coloured, I think, by the response of the noble Lord, Lord Vaizey—he did a bit of a U-turn halfway through what was a speech originally written in support. I am sure that he knows in his heart that this is the right one.
Really, the argument in this case is expediency versus justice. I think that choosing expediency, especially in the light of what the Constitution Committee had to say, would be extremely inadvisable. I was encouraged by the fact that the Minister is producing a memorandum in response to the Constitution Committee; we all wait with bated breath for when that arrives. In the meantime, I beg leave to withdraw my amendment.
My Lords, Amendment 164 is in my name and, I am delighted to say, that of the noble Lord, Lord Arbuthnot of Edrom. Sadly, he is tied up next door with matters of national security—I hope that I am not giving away any secrets—and is unable to speak to this amendment, but I value the support that he has given as a long-standing campaigner for changes to the Computer Misuse Act.
This amendment addresses a long-standing, globally recognised and increasingly dangerous absurdity in our criminal law: the fact that our primary cyber crime statute, the Computer Misuse Act 1990, criminalises the very cyber security professionals who are actively working to defend our country. The Computer Misuse Act is now 36 years old. It was drafted in 1990—an era before the world wide web had entered public consciousness, when less than 0.5% of the British public had ever sent an email and when the entire concept of proactive, ethical vulnerability research was completely unimagined. Because the Act was drafted at such a primitive stage of the digital revolution, it contains a blanket, indiscriminate prohibition on all unauthorised access to computer material. In its current form, it draws no legal distinction whatever between a malicious hacker, backed by a hostile foreign state and seeking to sabotage our critical national infrastructure, and an ethical, good-faith cyber security researcher—a “white hat” hacker, if you like—seeking to discover and responsibly disclose vulnerabilities before criminals can exploit them.
The real-world consequence of this statutory blind spot is that British cyber defenders are forced to operate with one hand tied behind their backs. Consider the day-to-day operational reality: if an ethical researcher in the UK scans an internet-facing network, identifies a critical zero-day vulnerability that leaves an NHS hospital dataset or a municipal water control system exposed, and takes the basic technical steps necessary to verify the flaw, they have technically committed a criminal offence under Section 1 of the 1990 Act. They face prosecution and imprisonment, even if their actions were undertaken entirely in good faith, strictly in the public interest and followed by immediate responsible disclosure to the National Cyber Security Centre or the affected operator.
I and others have received overwhelmingly passionate representations from the CyberUp campaign, representing what might be described as the elite of our domestic cyber security industry. Alongside the Criminal Law Reform Now Network and the NCC group, its evidence is stark. It says that the chilling effect of the Computer Misuse Act is actively undermining our national cyber resilience. Leading UK cyber security companies are routinely forced to prohibit their researchers conducting proactive threat intelligence gathering and vulnerability research on UK-based infrastructure because the legal risks are unacceptable. When British researchers identify an active cyber threat originating abroad, they are legally constrained from investigating the command and control servers if doing so involves touching a remote system without explicit owner authorisation.
Meanwhile, our international competitors have moved ahead. The United States updated its Department of Justice charging policies explicitly to protect good-faith security research. Countries such as Portugal, France and Australia have established clear and legal safe harbours for ethical cyber defenders. As a direct result, British cyber talent and commercial investment are migrating overseas to jurisdictions where proactive defence is recognised as a public good, rather than a criminal act.
During the Bill’s passage in the other place and during our Second Reading debate, the Government’s response was to agree with the principle of reform while arguing that this Bill is not the appropriate vehicle. Ministers pointed to an ongoing Home Office review and suggested that reform must wait for a hypothetical future security Bill. We have been waiting for the outcome of that Home Office review for more than five years; it was kicked into the long grass of Whitehall interdepartmental delays while our critical network remained under siege.
There is potentially a contradiction at the heart of the Government’s strategy on this issue. On one hand, Ministers are using this Bill to impose sweeping new legal duties and heavy, turnover-based penalties on operators to secure their networks; on the other hand, the Government continue to criminalise the very security professionals and ethical researchers whom these operators must hire to test and harden their systems.
Amendment 164 would resolve this contradiction cleanly, decisively and safely. It seeks to insert a direct substantive statutory defence into Sections 1 and 3 of the CMA. An individual charged under the Act would have a complete legal defence if they can prove that their conduct was reasonable for the detection or prevention of crime, or that they were carrying on legitimate cyber security activities, specifically defined in the Bill as vulnerability research, penetration testing, threat intelligence-gathering or a responsible disclosure necessary to safeguard system security.
Crucially, this amendment would not create a free-for-all or a loophole for malicious actors. It would empower the Secretary of State to approve a statutory code of practice, setting out the precise standards, rules of engagement and reporting protocols that constitute legitimate, good-faith cyber security activity. Anyone who acts outside those clear standards remains fully subject to criminal prosecution. Let us also consider the significant economic dividend of this reform. Independent economic modelling from the CyberUp Campaign demonstrates that introducing a statutory defence for legitimate cyber security activities would add 9,500 high-skilled, high-wage jobs and generate £2.5 billion in additional revenue for the UK economy.
We cannot build a resilient nation by preserving laws written for the floppy disk era. In an age of automated AI exploits and state-sponsored ransomware, we must unchain our cyber defenders. We have been here before, and the Government’s arguments for delay have run completely out of road. During our debates and correspondence on the then Crime and Policing Bill and, previously, the then Data (Use and Access) Bill, the Government repeatedly acknowledged the strength of our case. The noble Lord, Lord Katz, stood at the Dispatch Box and conceded that the Computer Misuse Act is dangerously outdated and that the Home Office were actively preparing a statutory defence under Section 1 to protect ethical cyber security researchers. Indeed, in correspondence following those debates, Ministers confirmed that engagement with industry and system owners was well advanced, but their stock excuse for resisting our amendments was always the same: “This is the wrong legislative vehicle. Wait for the upcoming cyber security legislation”. Well, here we are—this is the cyber security and resilience Bill. If primary cyber legislation cannot fix the statute that actively criminalises our front-line cyber defenders, what on earth can?
When the Government updated law enforcement powers under the Crime and Policing Act to seize domains and IP addresses, Ministers were quick to assure us that police powers are tightly bound by the Police and Criminal Evidence Act 1984 and statutory exemptions under Section 10 of the CMA. Yet independent security researchers, who discover over half of all critical system vulnerabilities before hostile state actors can weaponise them, enjoy zero statutory protections. They are left entirely at the whim of prosecutorial discretion and the threat of catastrophic legal action. The review of the noble Lord, Lord Vallance, recommended this defence three years ago. The CyberUp Campaign and techUK have drafted the ethical safeguards. In correspondence, Ministers have told us that they agree in principle. It is time to honour those commitments and put a direct statutory defence in this Bill. I urge the Minister to support this vital amendment. I beg to move.
My Lords, I strongly support the amendment from the noble Lord, Lord Clement-Jones, whether technically or in spirit. He is right to point out how outdated the Computer Misuse Act is and that its blanket prohibition on undertaking cyber security activities without any public interest defence is ridiculous.
The noble Lord’s amendment goes to the heart of the frustrations that have been expressed in debates on this Bill, particularly at Second Reading; sadly, I was not able to attend Committee last week, but I imagine they were reiterated again. This is an incremental and technical Bill that clears up some important anomalies. Time and time again, noble Lords have raised the point that it is missing the bigger picture. Now that we live in a digital age when absolutely everything depends on digital infrastructure, it seems to be absolutely extraordinary that we are not taking a much bigger view on updating our legislation, institutions, resources and skill base, to make this core infrastructure fit for purpose. It seems extraordinary to me that the Computer Misuse Act has not been touched for 36 years. It is well out of date. It may well be that there are other elements of it that have to be looked at.
Baroness Lloyd of Effra (Lab)
I am grateful to the noble Lord for raising this topic through his amendment, and I recognise the strength of feeling on reforming the Computer Misuse Act. I agree that the UK should have the right legislative framework to allow us to tackle the threats posed by cyber criminals.
The Home Office has already carefully reviewed the Computer Misuse Act and proposes to introduce a defence to Section 1 for accredited cyber security researchers when carrying out certain cyber security activity that would currently be unlawful under Section 1 of the CMA. The Home Office has worked closely with the NCSC, law enforcement and the cyber security industry to refine these proposals. The noble Lord, Lord Clement-Jones, was briefed by Home Office officials on these proposals in February, and I hope this is able to demonstrate meaningful progress that the Government are making on this issue. The Home Office recognises that legislating in this area is a priority and will do so as parliamentary time allows. As noble Lords here are all aware, the King’s Speech in May included a commitment to a national security Bill, with measures to update the Computer Misuse Act, and work is ongoing to bring forward this legislation.
The review proposed by this particular amendment would be undesirable because it would be limited to the scope of the NIS regulations. This would be too narrow for the scope of the Computer Misuse Act; it is also unlikely to provide the Government with new information on how the Act should be reformed. I am sure that the noble Lord and others in this Room will be active in the passage of this legislation once introduced. I have read his correspondence with the Home Office, including the activities that the noble Viscount, Lord Camrose, referenced, and his expertise across all these areas will be hugely welcomed once it is introduced.
I thank the Minister for that response. The noble Lord, Lord Vaizey, said that we know what the Minister will say: that it will be in a future piece of legislation. To that extent, we are pleased that at least we have a commitment to it, but this has been going on for an awfully long time. We tabled amendments during the passage of the Crime and Policing Act and the Data (Use and Access) Act. There has been plenty of time for the Home Office, or any other department to address this—DSIT could have taken this by the scruff of the neck—because it is such an egregious aspect of the current legislation.
I am pleased to hear that the Minister has read the correspondence. I hope she did not fall asleep while doing so; it is pretty interminable. She may well find that we come back to this on Report because, as she said at the beginning, feelings are running high about it. It is almost a demonstration of how not to run a Government. If you cannot get to grips with something as straightforward and important as this and just make a decision about it, that speaks volumes.
I thank noble Lords who have spoken today and demonstrated support across the board. On a light-hearted note, I say to the noble Lord, Lord Tarassenko, that of course Claude said that; it is trained on my speeches. As the noble Baroness, Lady Harding, said, this is self-evidently sensible. The trouble is, it is self-evident to us, but we despair sometimes, and the perfect must not be the enemy of the good. As the noble Baroness, Lady Neville-Jones, said, the objective is to put researchers in a safe position.
Finally, the noble Lord, Lord Vaizey, exhorted me to make sure that we have a date and a timeline. When will the national security Bill come forward? We saw it in the King’s Speech but I have had no contact from anybody in the Home Office about what they might insert in the Bill. I do not know whether anybody in this Committee has had notice of when a Bill might come forward. I think the Minister recognises the sheer impatience that most of us feel in this field, and I very much hope that, between Committee and Report, we can get some more clarity in this area for the benefit of all those researchers. In the meantime, I beg leave to withdraw the amendment.
My Lords, despite the fact that this is the last group, it is a really important area and this amendment rightly reflects that. We strongly support Amendment 174E. It would introduce a fundamentally elegant and highly necessary cyber security principle that the Bill has otherwise completely ignored: that of data minimisation and the proactive reduction of what is called our national data attack surface.
The most sophisticated cyber defence system in the world cannot protect data that has already been stolen. Conversely, the most ruthless ransomware gang or hostile state-sponsored actor cannot compromise data that was never collected or which has already been securely deleted. In the realm of digital defence, we must move past the narrow defensive mindset of simply building thicker walls around our databases. We must begin to ask a more fundamental strategic question: why are we keeping these massive, un-anonymised and highly vulnerable data honeypots in the first place?
The empirical evidence from our public sector is deeply alarming. We have received detailed and coruscating briefings from the Centre for Long-Term Resilience and our technical authorities. The National Audit Office’s January 2025 report on government cyber resilience revealed that approximately 28% of government technology is legacy software, leaving our public bodies highly vulnerable to attack.
Consider the catastrophic ransomware attack on the British Library in October 2023. When the library refused to pay a ransom of 20 bitcoins, the Rhysida ransomware group released 600 gigabytes of stolen customer and staff data on to the dark web. The library’s own subsequent post-mortem was clear: its reliance on legacy applications and older network designs substantially and unnecessarily increased the volume of sensitive customer data sitting on the network. This was data hoarding, plain and simple, and the price was paid by the British citizens whose personal details are now permanently compromised.
Consider the hack by ExfilSquad, when normal teenagers living with their parents managed to breach a public database, leaking the sensitive personal details of 100,000 police officers and staff on the dark web, alongside data from the Ministry of Defence and the Department for Education. How did they do it? They did not deploy supercomputers or advanced zero-day exploits, they simply exploited a basic, misconfigured Power Pages database. The hackers’ own boast on the dark web was chilling. They said the data was accessible without any authentication whatever.
Why are these databases so large? Because our public bodies routinely collect and indefinitely retain vast, sprawling, unanonymised datasets, from birth certificates and benefit records to housing benefits and electoral roles, without any systematic statutory drive to minimise or anonymise them. That is why the Association of British Insurers and the NCSC both advise that data encryption and data minimisation are critical to reducing the leverage that a threat actor has in ransomware attacks. By rendering exfiltrated data unreadable through encryption—or better yet, non-existent through deletion—we take away the hackers’ ammunition.
While the Bill focuses heavily on the administrative paper exercise of incident reporting, it remains completely silent on the contents of the databases themselves. Amendment 174E would provide a strategic corrective. It would legally oblige the Secretary of State to open a public consultation within one month of the Bill’s passing to evaluate the cyber-resilience benefits of minimising data collection and increasing data anonymisation across our public bodies. By forcing our public sector to lead by example, this amendment could begin the vital work of shifting the UK towards a genuine resilience-by-design model. It would reduce our vulnerability, harden our national defences and protect the digital lives of our citizens. I urge the Minister to accept this vital safeguard.
Baroness Lloyd of Effra (Lab)
I thank the noble Lord, Lord Markham, for raising this important issue again. Good data hygiene and security is essential to ensuring that public bodies are resilient to cyber attacks. Through the Bill, we are better protecting data, to make our essential services safer and more secure for all those who rely on them. This includes through security and resilience requirements, which will form part of the duties placed on regulated entities and which I have mentioned at previous sittings of this Committee. In our consultation later this year, we will propose that these requirements cover data security.
Let me emphasise that where personal data is concerned, all public bodies must already comply with the data protection principles in the UK GDPR. This includes requirements to keep personal data secure, process only the minimum amount needed to deliver their objectives, periodically review whether this data is relevant and adequate for the public body’s purposes and not to retain this data for longer than is necessary. The Information Commission regulates the data protection legislation independently of the Government. It has a range of powers at its disposal to investigate alleged breaches and require public bodies to address non-compliant practices.
Significant obligations exist under the UK GDPR. In addition, our upcoming consultation will examine measures to strengthen data security within the security and resilience regulations. A separate consultation, as proposed by the noble Lord, would not be a good route through, but it would be a good idea for us to meet and think about the most appropriate route for advice on data security in the context of the SRRs. I suggest that we focus our discussion on the SRRs in the intervening period.
As this is the last time I will speak in Committee, I want to reflect on some of the points made by noble Lords. Obviously, productivity and growing the UK economy are big themes for all of us. It is true that we have progressed through Committee faster than perhaps people anticipated, but I have heard very clearly the points that have been made very succinctly, both on fundamental structural issues—to which, as I have said, I think the approach in the Bill is right, I am just logging the fact that I have absolutely heard the motivation for that, around consistency and so on—and indeed on some of the more technical points that noble Lords have made about some of the details of the Bill, some of which I have already undertaken to come back on.
I thank the Committee for its scrutiny and noble Lords for the experience they have brought to the Committee from their practical walks of life.