Cyber Security and Resilience (Network and Information Systems) Bill Debate

Full Debate: Read Full Debate
Department: Department for Science, Innovation & Technology

Cyber Security and Resilience (Network and Information Systems) Bill

Lord Holmes of Richmond Excerpts
Lord Holmes of Richmond Portrait Lord Holmes of Richmond (Con)
- View Speech - Hansard - -

My Lords, it is a pleasure to take part in this Second Reading debate and to follow my friend, the noble Viscount, Lord Colville of Culross. Though he, by his own words, repeated some of the earlier points, he was the first speaker to say “lacunae”, for which I am particularly grateful; it sounds like a technology company. I declare my technology interests as set out in the register, as advisor variously to the Crown Estate and to Simmons & Simmons LLP.

As has been noted, this Bill is significant by having “cyber” in the title. This is long overdue, much needed and critical, as the Minister said, taking a cross-sector approach to cyber. Yet the first interesting point is that the Bill does not do that. Most notably, it is extraordinary that neither food nor space are included in the Bill. Similarly, it is said to take a cross-economy approach, yet it does not. However, it is worth mentioning the two sides of that economic coin and the huge economic growth potential from our cyber industries. I echo all the points that have been made about the need for skills and education, and to enable the cyber sector to grow and deliver that economic benefit.

Reporting has been mentioned widely throughout the debate. It is unfortunate if one finds themselves in a situation such as that of my noble friend Lady Harding, with multiple agencies to have to report to. Surely it would make sense to have a single reporting point for the speed, efficiency and effectiveness of that reporting system. Similarly, there is so much opacity around many of the definitions within the Bill. I pull out “significant impact” as one of them. What does this mean? If it stays as set out, the natural and understandable response from business is to go for the low-level mass reporting to avoid regulatory intervention. Does that enable the economy and the country to be better protected in this respect? I think not.

Similarly, the 24-hour and 72-hour reporting requirements feel oddly constructed around the artificial concept of a day set out in 24 hours. When one considers the real-time velocity of these attacks, it would seem logical that something way ahead of 24 hours would be advantageous at that stage and potentially something extending beyond 72 hours to do the second bit of the reporting process. What evidence is there to support this quite arbitrary 24 hours—or, as otherwise described, a day?

Security and resilience are the concepts most central to the Bill and will be the markers of its success or otherwise. For issues around proportionality and the ability to evolve and develop, does the current structure of the Bill really optimise this? MSPs have already rightly been mentioned. The burden for them is overbearing as currently set out. Surely it would make more sense to have a concept around what is reasonable for MSPs to oversee, what can legitimately be seen as within their control and how they can evidence that.

Understandably, the multiple regulator issue has been well discussed. It is critical, because how will we have co-ordination across all those organisations? A forum is certainly not the solution, as my noble friend Lady Harding rightly set out. A lead regulator, a single regulator or something around that has to be the way to go. I would argue that the NCSC should have the loudest voice in determining what is the best model and the best structure for doing that.

I was interested in the Minister’s introduction. She talked about the criticality of cross-sector consistency. I agree entirely, but in a debate on AI on 4 June in Grand Committee, she argued that consistency was not necessarily a central principle for the Government in the regulation of AI. I believe that a true cross-sector approach to cyber makes sense in this Bill. We can add to what is currently there and make that happen, but it is surely logical, and indeed a consistent approach to consistency, that we take that approach with AI. Can the Minister say why, if this argument is good for cyber, it is not good for AI—with a cross-sector approach, as will benefit this Bill, that is principles based and outcomes focused, with inputs understood?

I have another point on consistency. When the Minister sums up, can she set out the advantages that she sees in all the divergences that the Government have taken from the EU’s NIS2? I would be interested to hear the Government’s arguments for the advantages that they are seeking to bring from that.

My noble friend Lord Arbuthnot has rightly mentioned the CMA, and I know that my friend, the noble Lord, Lord Clement-Jones, will also mention this. It is right to mention it in this Bill, even though the national security Bill is said to be the vehicle through which this will come forward. It is right to give it a run around the track in the legislative process with this Bill, because we are talking about coverage currently holding our cyber professionals back because of a 1990 statute. To give some sense of what that means, in 1990 it had been only 24 years since England had won the World Cup. It is in urgent need of reform. We need to empower and enable our great cyber security professionals to do their job.

I have a quick point on DVS. I am not sure the Minister was involved when we did the Data (Use and Access) Act, but there was rightly a lot of discussion around DVS. In some ways, parts of this Bill are the other side of that coin. Currently we have a situation that is not addressed in the Data (Use and Access) Act or in this Bill: what happens to verification services when they have an attack where synthetic data is injected directly into the data stream, in effect bypassing the camera to get verification? How does this Bill address that issue? Do Clause 12, the potential regulations under Clause 30 or the guidance under Clause 36 address this? If not, what is the Minister’s view as to how we address that critical issue around synthetics?

The success of the Bill and of cyber in the UK will rest so heavily on the shoulders of our cyber security professionals, the women and men who do so much to keep our system—and, through that, us—safe. We owe them so much. Understandably, they often do this in the shadows, in dark rooms and in the Doughnut. We give them our sincere thanks, and we must demonstrate that thanks through the amendments we bring forward to make the Bill better.